Skip to main content

How sign-in works

The app uses the device sign-in flow (RFC 8628). You sign in on the OfficeLabs website in your browser. The app never sees your password.

The code​

  • The code has two groups of four characters, like ABCD-EFGH. Look-alike characters are left out.
  • It expires after 10 minutes.
  • The account panel shows the code. Approve only if the page in your browser shows the same code.
  • The app checks for approval every 5 seconds. If the service asks it to slow down, it waits 5 seconds longer.

Where the credential is stored​

The app keeps one file, cloud.credential. It holds a refresh token, a session ID and the service address.

SystemLocationProtection
Windows%LOCALAPPDATA%\OfficeLabsEncrypted for your Windows user
macOS and Linux~/.officelabsFile readable only by you, folder accessible only by you

The short-lived access token is kept in memory only and is never written to disk.

Refresh​

  • The access token is renewed when less than 60 seconds remain, one renewal at a time.
  • A computer that has not refreshed its sign-in for 90 days is signed out. 365 days is the outer limit.

Offline behaviour​

  • If the cloud cannot be reached, or returns a server error, you stay signed in. The app keeps the token and retries at most every 30 seconds. The panel says it cannot reach OfficeLabs, and offers Try again and Sign out.
  • You are signed out only when the service rejects the refresh token.

Document author​

After your first sign-in with an account, the app fills any empty name, initials and email fields in LibreOffice's user data (Tools > Options > User Data). Fields you already filled are left alone. The name becomes the author of documents you save. To change or clear any of these fields, edit them in Tools > Options > User Data.